The developments that changed the register, most recent first, plus a live wire of headlines in the sidebar. For the machine-readable version, take the RSS feed.
California vetoes the sensitive-data sale ban and signs the deletion and data broker bills
Governor Newsom returned AB 1542 without his signature, writing that a categorical ban on sharing sensitive personal information was a step too far when consumers already hold a right to limit its use, and that the bill carried costs not in the 2026 budget. The same day he signed SB 923, which extends the CCPA right to delete to data a business obtained from third parties and requires online-only businesses to offer a webform for requests, and AB 883, which adds an accessible deletion mechanism for data brokers and a deletion process for elected officials and judges. Both take effect 1 January 2027. SB 690, the CIPA pen-register reform, and AB 2561 on privacy settings were still on his desk, with 30 September the deadline.
TikTok drops its appeals and accepts the ICO's GBP 12.7M fine
TikTok withdrew its appeal against the 2023 penalty for processing the personal data of UK children under 13 without parental consent, along with its appeal against an information notice about how its recommender systems process 13 to 17 year olds' data. The withdrawal followed an Upper Tribunal ruling in August that rejected TikTok's artistic-purposes argument, and the ICO says it will now progress that investigation. The regulator itself becomes the board-led Information Commission on 30 September under the Data (Use and Access) Act 2025.
Philippines puts Meta, Roblox, Reddit and Discord on notice
The National Privacy Commission issued show-cause orders to the four platforms over registration requirements under the Data Privacy Act, part of an intensified push on how digital platforms handle children's data.
Ireland fines Google EUR 403M over location data
The Data Protection Commission found that Google processed location data from Location History and Web & App Activity unlawfully and unfairly between May 2018 and February 2020, fell short on transparency across those features and Location Accuracy, and kept location data too long. Google has six months to bring its processing into compliance.
EDPB proposes a common method for deciding when to fine
The EDPB adopted Guidelines 04/2026 on whether to impose administrative fines, a five-step method that complements its 2022 guidance on calculating them, and opened consultation until 13 November. It also adopted the final version of its guidelines on the interplay between the Digital Services Act and the GDPR.
Korea's 10% fine ceiling takes effect
A PIPA amendment passed in February now allows fines of up to 10% of total revenue for repeat intentional violations, incidents affecting 10 million or more people, and breaches after an ignored corrective order.
Chile moves to delay its new data protection law by a year
The government filed an urgent bill to push Law 21.719's start from 1 December 2026 to 1 December 2027 and enlarge the new agency's board from three members to five, after the Senate rejected the nominees and the agency could not be constituted. Until Congress acts, 1 December 2026 remains the legal date.
California sends a sensitive-data sale ban and CIPA reform to the governor
The Legislature closed its session by passing eight privacy bills, headlined by AB 1542, which would replace the CCPA's opt-out for sensitive personal information with a prohibition on selling or sharing it, and SB 690, which would end private pen-register lawsuits under CIPA for website and app tracking, retroactively. SB 923 expands deletion to data collected about a consumer from third parties, AB 883 tightens data broker timelines, and AB 2561 would stop operating systems and apps from overriding users' privacy settings. Governor Newsom has until September 30, and signed bills take effect January 1, 2027. The signed AB 2246 has already replaced the court-blocked Age-Appropriate Design Code.
Turkey restricts targeted advertising to children
Amendments to Turkey's commercial advertising regulation took effect, requiring targeted ads to tell consumers which criteria selected them and how to change them, banning profiling-based targeting of known children, and requiring AI-generated endorsements to be labeled.
Japan promulgates its APPI amendment
The Diet passed the triennial-review amendment to the Act on the Protection of Personal Information on 10 July, and it was promulgated on 17 July as Act No. 56 of 2026. Criminal provisions take effect on 17 January 2027 and the rest, including administrative surcharges, AI and statistics consent exceptions and parental consent for under-16s, by 17 July 2028.
Vietnam's new Cybersecurity Law takes effect
Vietnam's consolidated Cybersecurity Law entered into force on 1 July 2026, completing a three-law rebuild (PDPL, Data Law, Cybersecurity Law) that began in 2025 and leaves foreign platforms with layered filing and classification duties.
The July 1 state amendment wave: Connecticut, Utah, Arkansas and Virginia
Connecticut's CTDPA amendments took effect, lowering the applicability threshold to 35,000 residents, pulling in any business that processes sensitive data or sells personal data, and adding impact assessments for significant profiling. Utah's amendments landed the same day, Virginia banned selling precise geolocation data, and Arkansas's Children and Teens' Online Privacy Protection Act extended COPPA-style rules to teens and banned targeted advertising to minors. Arkansas still has no comprehensive consumer privacy law.
EU Council adopts the AI half of the Digital Omnibus
The Council formally adopted the Digital Omnibus on AI, delaying and adjusting parts of the AI Act. The data protection half, which would amend the GDPR and cookie rules, remains in negotiation, with the Council's June text dropping the single-click reject duty and the consent-banner moratorium.
Cameroon's data protection law takes full effect
The 18-month transition under Law No. 2024/017 ended, so its obligations now apply, although the presidential decree creating the supervisory authority has not been issued.
Second wave of UK DUAA provisions commences
Further Data (Use and Access) Act 2025 provisions took effect on 19 June 2026, one year after Royal Assent, including the duty on controllers to handle data protection complaints. The staged rollout began with the main data protection package on 5 February.
Korea imposes a record KRW 624.7B penalty on Coupang
The Personal Information Protection Commission penalized Coupang over a breach affecting 37.5 million people and, separately, KRW 201.1B for collecting 11.17 million members' activity on third-party websites and apps through its Coupang Partners affiliate program. The total is a Korean record.
Connecticut bans selling precise geolocation data
Governor Lamont signed SB 4, which bans selling precise geolocation data and adds facial recognition transparency duties from 1 October 2026. Companion bills restrict surveillance pricing from the same date and create data broker registration from 1 January 2027.
California settles with GM for $12.75M over driving data
The Attorney General, the California Privacy Protection Agency and local prosecutors reached a $12.75M settlement with General Motors over driving behavior and location data sold to data brokers without consumers' consent, the largest CCPA settlement to date.
Bangladesh enacts its Personal Data Protection Act
The Personal Data Protection Act, 2026 replaced the interim government's 2025 ordinance and is treated as in force from 6 November 2025, except the chief data officer, complaints, fines and compensation provisions, which await a government notice at least 18 months after enactment. A separate act creates the National Data Management Authority as regulator.
Japan's Cabinet approves APPI amendment bill
Japan's Cabinet approved the triennial-review APPI amendment and sent it to the Diet: consent exceptions for statistics and AI development, under-16 parental consent, and stronger PPC enforcement, with implementation to follow through PPC rules.
EDPB launches its fifth coordinated enforcement action
The EDPB kicked off its 2026 coordinated enforcement framework on 19 March, sweeping a single compliance topic across dozens of national authorities simultaneously, the annual exercise that has previously covered DPOs, access rights and erasure.
Brazil's ECA Digital takes effect
Brazil's online protection statute for children and adolescents entered into force six months after its September 2025 enactment. It requires age assurance and parental tools, bars profiling-based advertising to minors, and is enforced by the ANPD, which became a full regulatory agency in February.
Burundi enacts its first data protection law
Law No. 1/03 took effect on promulgation, giving private-sector processing six months to comply and the public sector a year. The Personal Data Protection Agency it creates still needs an implementing decree.
UK's DUAA data protection provisions go live
The bulk of the Data (Use and Access) Act's changes to the UK GDPR, DPA 2018 and PECR commenced on 5 February 2026 under SI 2026/82, with the ICO racing to finalize guidance and signaling it will assess conduct against the rules in force at the time.
Saudi Arabia publishes its first PDPL enforcement decisions
SDAIA's violation committees announced 48 decisions under the Personal Data Protection Law, including penalties for sending advertising and marketing messages without the recipients' consent. Penalty amounts were not disclosed.
Three more US state privacy laws take effect
Indiana, Kentucky and Rhode Island's comprehensive laws took effect on 1 January 2026, bringing the in-force count to twenty. Rhode Island arrives with a 35,000-consumer threshold, among the lowest in the country, and no cure period.
Vietnam's Personal Data Protection Law enters into force
Law 91/2025 and implementing Decree 356/2025 replaced Decree 13, moving Vietnam's consent-first privacy regime from decree to statute with impact-assessment filings to the Ministry of Public Security.
California's ADMT, risk-assessment and audit regulations take effect
The CPPA's regulation package on automated decision-making technology, risk assessments and cybersecurity audits took effect on 1 January 2026 with staged compliance. The automated decision-making rights (pre-use notice, access and opt-out) become operative on 1 January 2027, and cybersecurity audit certifications phase in from April 2028. Together they are the biggest expansion of CCPA duties since the CPRA itself.
Brunei's Personal Data Protection Order takes effect
Most substantive duties under the Personal Data Protection Order 2025 took effect after a one-year grace period, making Brunei's first private-sector privacy law enforceable by AITI.
Delaware's cure period expires
Delaware's DPDPA cure period ended 31 December 2025, the first of several sunsets (Montana follows 1 April 2026) that let state AGs move straight to penalties without a fix-it warning.
European Commission proposes the Digital Omnibus
The Commission proposed its Digital Omnibus package, pairing GDPR and ePrivacy amendments (cookies folded into the GDPR, machine-readable consent signals, a single breach entry point, a narrowed personal-data definition) with AI Act changes. The EDPB and EDPS later backed the simplification goal while raising key concerns in a joint opinion.
India notifies the DPDP Rules, starting the compliance clock
MeitY notified the DPDP Rules 2025 on 13 November, bringing the provisions that establish the Data Protection Board into force immediately. Consent-manager provisions follow on 13 November 2026, and the substantive duties, the Board's enforcement powers and penalties of up to INR 250 crore apply from 13 May 2027.
Israel's Amendment 13 takes effect
The largest reform of Israeli privacy law since 1981 entered into force, arming the Privacy Protection Authority with administrative fines and modern GDPR-style definitions.
Commission moves to renew UK adequacy to December 2031
The Commission published draft decisions renewing both UK adequacy findings after assessing the Data (Use and Access) Act. The renewals were completed before the old decisions lapsed at the end of 2025 and run to 27 December 2031, subject to monitoring.
Vietnam passes its Personal Data Protection Law
The National Assembly passed Law 91/2025/QH15, giving Vietnam a statute-level privacy law effective 1 January 2026 and confirming the consent-first, filing-heavy model of Decree 13.
UK Data (Use and Access) Act receives Royal Assent
The DUAA became law, amending the UK GDPR, DPA 2018 and PECR with recognised legitimate interests, direct-marketing acknowledgments, cookie exceptions and PECR fines aligned to UK GDPR levels.
Russia's turnover-based leak fines take effect
Russia's liability overhaul introduced turnover-based fines (to 3% of revenue) for personal data leaks plus criminal exposure for data trafficking, sharply raising the cost of breaches involving Russian citizens' data.
Mexico's new federal privacy law enters into force
The rebuilt LFPDPPP took effect one day after publication, preserving ARCO rights and tacit consent while moving enforcement from the dissolved INAI to the executive-branch SABG.
Commission moves to withdraw the ePrivacy Regulation
The Commission's 2025 work programme listed the ePrivacy Regulation for withdrawal after nearly a decade of deadlock, leaving the 2002 Directive and its 27 national implementations as the EU's cookie law for the foreseeable future.
Canada's privacy reform dies with prorogation
Bill C-27, which would have replaced PIPEDA with the CPPA and added an AI law, died when Parliament was prorogued in January 2025, leaving Canada's federal regime without fining powers while Quebec's Law 25 sets the national pace.